All articlesPrivacy

Article 28 GDPR requirements: the complete DPA checklist for 2026

A deep-dive, checklist-driven guide to Article 28 GDPR — every mandatory DPA clause, sub-processor rules, SCCs, breach timing, and audit rights explained.

July 22, 20266 min read· By ContractScan AI

What Article 28 actually says

Article 28 of the EU General Data Protection Regulation governs the relationship between a controller (the business that decides why personal data is processed) and a processor (the vendor that processes it on the controller's behalf). It requires a written contract — a Data Processing Agreement, or DPA — that binds the processor to a specific, non-negotiable set of obligations. Skip the DPA and both parties are in breach, even if the underlying processing is otherwise lawful. Fines under Article 83(4) can reach €10 million or 2% of global annual turnover, whichever is higher.

If you're new to the controller/processor distinction, start with our Data Processing Agreements explained primer, then come back here for the clause-by-clause checklist.

The Article 28(3) mandatory clause checklist

Every compliant DPA must cover these eight elements. Use this as a red-pen checklist when reviewing a vendor's template.

  • Subject matter and duration. What personal data is being processed, and for how long. "Duration of the underlying services agreement" is acceptable if the MSA has a clear term.
  • Nature and purpose of processing. Storage, analytics, support, hosting, AI training — spell it out. "General SaaS services" is not specific enough.
  • Types of personal data and categories of data subjects. Names, emails, IP addresses, uploaded files; employees, customers, end users, minors. Special-category data (health, biometric, political) triggers extra obligations under Article 9.
  • Documented instructions only. The processor may only act on the controller's written instructions, including for international transfers. A catch-all "as reasonably required to provide the service" clause is fine as a baseline, but the controller must retain the right to issue further instructions.
  • Confidentiality of personnel. Every person authorised to process the data must be under a statutory or contractual duty of confidentiality.
  • Security measures under Article 32. Encryption in transit and at rest, access controls, backup, incident response, regular testing. Modern DPAs reference an ISO 27001, SOC 2 Type II, or equivalent certification instead of listing controls inline.
  • Sub-processor authorisation. Either specific prior consent for each sub-processor, or a general written authorisation combined with a public sub-processor list and 30 days' notice before adding a new one, plus a right of objection.
  • Assistance obligations. Help with data-subject rights requests (Articles 15–22), breach notifications (Article 33), Data Protection Impact Assessments (Article 35), and consultations with supervisory authorities (Article 36).

If any one of these is missing or hand-waved, the DPA is not Article 28 compliant — regardless of what the header says.

Sub-processors: the clause that gets litigated

Sub-processor chains (your vendor's vendors) are where most DPA disputes originate. A defensible sub-processor clause requires all of:

  • A public, up-to-date list of all sub-processors, with name, location, and processing activity.
  • 30 days' prior written notice before adding or replacing a sub-processor (some regulators expect 60 days for high-risk changes).
  • A right to object on reasonable data-protection grounds, with a mechanism to terminate the affected service if the objection can't be resolved.
  • Flow-down of equivalent terms. The processor must impose the same Article 28 obligations on every sub-processor by contract.
  • Liability continuity. The processor remains fully liable to the controller for the sub-processor's acts and omissions.

The EDPB Guidelines 07/2020 on controller/processor concepts remain the authoritative reference for how regulators interpret these obligations in 2026.

International transfers after Schrems II and the DPF

If any sub-processor is outside the EEA, the DPA must document a valid transfer mechanism:

  • EU-U.S. Data Privacy Framework self-certification for U.S. recipients (in force since July 2023).
  • Standard Contractual Clauses (2021 modules) for anywhere else, with the correct module (C2P, P2P, etc.) selected.
  • Transfer Impact Assessment (TIA) covering local surveillance law, government-access requests, and supplementary measures such as encryption with customer-held keys.
  • UK addendum or IDTA for transfers involving UK personal data.
  • India DPDPA notification where the Digital Personal Data Protection Act 2023 restricts the destination country.

A DPA that references "SCCs" without specifying the module and without a TIA is not export-ready.

Breach notification timing

Article 33 gives the controller 72 hours to notify the supervisory authority once "aware" of a breach. To hit that clock, the DPA should require the processor to notify the controller:

  • Without undue delay, and in any event within 24 hours of becoming aware.
  • With a defined minimum payload: nature of breach, categories and approximate number of data subjects and records, likely consequences, measures taken.
  • Through a named contact channel — a monitored security inbox, not a generic support ticket.

"Prompt" or "reasonable" notification without a numeric SLA is a red flag; you can't build a 72-hour compliance workflow on it.

Audit rights that survive a real audit

Article 28(3)(h) requires the processor to make available all information necessary to demonstrate compliance, and to allow for and contribute to audits. In practice, controllers should insist on:

  • Annual delivery of the latest SOC 2 Type II or ISO 27001 report.
  • A written questionnaire response (SIG Lite, CAIQ) refreshed annually.
  • A contractual right to on-site or remote audit with reasonable notice, typically once per year unless a breach or regulator request triggers more.
  • Regulator cooperation — the processor must accept direct audits by the supervisory authority without gatekeeping.

Watch for clauses that cap audit costs at the controller's expense or restrict audits to the processor's own auditors — both are common tactics to make the right theoretical.

Return or deletion at end of services

At contract end, the processor must, at the controller's choice, return or delete all personal data and delete existing copies unless retention is required by law. Your DPA should specify:

  • The format for returned data (machine-readable export, not a PDF dump).
  • A deletion deadline — 30, 60, or 90 days is standard.
  • A written certificate of deletion, including backups and any residual copies with sub-processors.
  • Any statutory retention exceptions the processor is invoking, with the legal basis named.

Common Article 28 failure patterns

From reviewing thousands of vendor DPAs, these are the recurring gaps:

  • "Processor may use sub-processors as it deems appropriate" — no list, no notice, not compliant.
  • "Processor will notify controller of security incidents promptly" — no SLA, breaks 72-hour timing.
  • Audit rights limited to "the processor's most recent SOC 2 report" — no right to independent audit.
  • Transfers "handled in accordance with applicable law" — no named mechanism, no TIA.
  • Deletion "within a reasonable time" with no certificate — unverifiable.
  • Liability caps that also apply to the DPA — controllers should push for uncapped liability for wilful GDPR breaches.

Where AI review speeds this up

Reviewing a DPA against this checklist by hand takes a competent privacy lawyer 45–90 minutes. ContractScan AI runs the same eight-clause Article 28 audit, flags missing SCCs and TIAs, checks breach-notification SLAs against the 72-hour rule, and produces a one-page DPA scorecard in under 60 seconds — with a plain-English explanation of every gap. For procurement teams triaging dozens of vendor DPAs per quarter, that's the difference between a bottleneck and a workflow.

Upload a DPA to the contract analyzer or start with the free red-flag scanner to see the checklist in action.

Further reading

#gdpr#article-28#dpa#privacy#compliance

Stop reading contracts. Start understanding them.

Upload any PDF or DOCX and get a plain-English summary, risk score, and negotiation suggestions in under 60 seconds.

Try ContractScan AI free

Keep reading